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[IBfc^fi] ffiKtt* 1-1-1- nTB. 
TS. 1 - 1 - 1 - n «, ttMHNItqNMttt 

3-D©»ftif-^4-l~4-3^jM 
•5. mtt^-^U- 1-4-3 «. rtflWOtfigf* 
H*JU 8KrtS«c*-3t,»-C»fr*ff5. WUBfTft. 

1-4 -3#J|UK • *trl/fcS*li** 
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(2) 

1 

OTB«*«*«cfctf sitEiaai**. ma* ^9-5 
iriBlSaEilB*^ 0 r itifsa&Ilffi*** 6 ©«W< b&Mrt 

aifSVfKSfc'Xf-A. 10 
[»*S2] MIB&Ilig^B. 

tsasc^tct^tftonfcfiairtSiHi^bi/r. mi©ng 

^{bsasrtSfc&s-ram 1 ©B§^{t#si. 

HEW l ©«HWl*®tcJ: r>Bg#<t$tt/tm l coBf^-fb 

aurts* nwft 0 x % 2 ©ng-st < usurt 5 
j* 2 ©**«*»£ *jmu 

fc* 2 ©bi #{ta3Srtg*a# ur^iam i ©m#{ta 

IW»*»T**1©WWI*R*JI«U WBJIlt 20 

BugasaE^s©Buiam 1 o'&mwmt zvmztitt 
•sin 2 ©aw*t#R*juw* c £ r sm&i 
[h#ji 3 j maw i mmtmstit, 

TiflMWbU f£mi©&iia*. HulBmitggcm 1 © 
&RJ«*Bt>TBg#<bU 

iriem2©B§#{b#-SB. 30 
miam i omtt&KAS*. m2 ©s«a*fflt»r«i 
-subu tt)*2©ftaft*. friBi25E^s©m2©&gg 

Hem i ©a»ft#gH*. fb<*ft/cm2 ©*jist 

#15 £, 8[#ShA:J|l2©*a«*flH,>r. iFiBm2© 
aWHWBWtMl/TinBIl l ©*# {b&IlrtS* 

«» r 5 * 2 ©«#{ kswrt«a#f b#a £ ** * . 
iwa*2©a#{b*aB. Bg-^{b$nfcmi©SiiH 40 
4. uK»i©5»Bai«:»(&r5aii©tt«a*»i>r 

«^ ttmigB^ 1 ©SiMI*K»r4» 1 ©SiMfflHt 

©**rt8awsa«fl*R4 5 c £ -r 

5iS*9 2 iBi&©fi*&IS->* r A. 
[11^114 ] B5fB!2fiE&gB. 
Saf#©Eatt*BHr^ < . WSaB88*tc «fc 0 Bg-sf 

{bsti/cja^wsK:^ iT77 > ks«44js-ts^ 

9 -f > K»S#S4«*.. so 
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IMB&lBIStt. 

J: "5 3ft 2 ti1tim%ictt&* 5 Bg 
■fttU *J83E!BE»HlCjil<fr5»3©Bi^b#S£ > 
filBI2agg©-/7 4 > F§£#8«:J: 1 ftfc:/ 

{f&5£ £ 4EM8£* 5M5RJ51 &t>t3 ©t>r#a*>© 
IBSS©S^S:m->Xf A. 
[M#J«5] UiBfts+^SB. 
B5IBaMrtgCcML-Ci^iJtf#6^^-r5^iJtffE^fiX 
3M8£. 

£*JUTr * C £ *fc*£ T SS|J»H 1 fci> t 4 ©t»r 
ft*>©fB4£©miP&II->* fA. 

[ n#m 6 ] i?gBS i ©&MM* «t w» i ©ssk 

<c Cf (CtnBIH 2 <D&nM*s J: Cf m 2 «>%m«i» . -s 

- Frtrftrt • «a s ft* c £ *t#$t £t *m*Ji 3 u 
i^l 5 ©^-rn*^©iBis©^^->x7- a. 

Sudani, . 

isa^snfca^g^Bg^bor, *e*»H7-* 

tcS&s ft fcBSgiltc jgft u . 

mriBisaE^ats. «3K#©BE*m». HKSftfc*ia 

B. fIlBBg^b$nfc^g=&B5IB«ft^g(ci*{iL. 

B(riB*tt«s«: J: -3 "CtwatHMtSWrtSfca* 

»sairtSK*-5i»-c««i#©» sresst-r 5 c i 
»£-r**^«iim 

[»*S8] t!ilBig^*B > BulBS^rt§?rBg^{b 

br^basirtstajab. 

ffiBSSESSBB. ^IBiSM^KiOBg^b^n/cBg^ 
{bSRrtSKWOT^v-f >F*«S4fiSL. 
KreSOfll^B. «fB^5-/>F»*36»e»»«1f«4R 
JfT 5 C £ «1$tt £ f 7 K»©«^««*ffi. 

[ n«9 9 J «E«W9S©lt^fcT tt . 
ItriBSaWKJ: OfffchfcffiKrtSt, » l ©£«§!£ 
fflUTBg^bur Miami ©Bg^bSMrtS^t^u, 
ffiam 1 ©£aa*. B5ia»itKs©m 1 ©&sa««^ 

^•CBg^{bL, 

luiam 1 ©e^bsairts*. m2©*ast%fflo-cBt 
fjiam 2 ©«ji^^ . s?iB?sE^s©m 2 ©^nn^ffi 

^■CBg^bL/. 

iWB>w{ba3iirts©a#fbrtt, 
friBBg#{b£*a/cgi2©«jia*. miesi2©&ntt(c 
*K6-r4»2©aw«*fflt»-ca#b«r«rsB»2©»a 

Buiea-ven/c:m2©sii^ffiiir. iriBm2©Bg-^ 
itistwm^im^xtmm 1 ©Bg^^bSMrts^mif 
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U 

ButsBg-^it $ titcmi ©SiiM* . fiie» 1 (DAmmic 
Miti-sf i mmmzm^-cm^b-cm&gi i ©sji 

BSEa-f Sttfc* 1 ©£jIgt£ffl(,>T. SuIB^ 1 ©Bg-sf 

tt&nrtg *a-§ t -ctssflg * ik# ? 4 c i £ 
r 4s*#ji 7 ES^m^n^?*. 
m?m i o ] m&®mfis®icML-cim\mz£.f$. 
o . ire&aOTStireau'Jfltft t £ & tc sa-r 5 c t 
*#a£-r 7 &i> l 9 ©^ma^Eis©*^ io 
sum 

l l ] ftfEU 1 ©4iH»s«tCf» 1 ©«* 
£1. & 6 C^tc MESS 2 <D£mmis J: t/S! 2 ©«HBHtt . 
«*. BE^*fcB*l1-SIItC*BlaJtt&. fl-gPMt 
$R#iB»l/ttl>J:5CC7 , ci?-* VStitc, I C*- Frt 

0 ©l»-j**i*>CCEtt©«*!BK:£ft. 
[OOOl] 

Ptt£*©ta3l{cfflc>r*?a^* : ffi^->xrAte < fcc;s 

[0002] 

[ffi*©8«] HRa*Mt£a*&£©» 

K&UfflffiSrm*. £<©A^-Clttf 

oaaifflis{c»*nfc<wt#ifcg*iti8, # 4 

[0003 ] 

[H9Jj!flgj*LJ:5£T4g&jS] L/rt>l/ft#6. JJO 30 

*5. *fc. 8X*ft£B> «**{CJ:5*«*T*5 
tab. EAsafc*5*^**W»W6*.«a». * 
fc. AK«tSBa*Br*-5A;«>. Hit 5 X feiti 9 f# 4 

[0004 ] C©»WBJ^Lfc*t*fc«*TttStlfc 

t©T. A#©B'M. panx^-*©*!^. asanas 

Fp1M©1f & . *tt 5 * ©BS±**3S-r 5 C £ jOT? § 5 * 

wi-rs. 40 

[0005] 

5fc&tc. IHH 1 EiScfHBTB. * ?» h 9 - 
WWtU i«^b&JIrt3££)&T4&Mii&*£. It 
^■OrBE-r*KiESS£. BJEISIE^g^^tTBtrE 

6©8#{fc8sirts*«# iz-caawssBi 

tt*B£*=SUIT5C 4. 50 
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[ 0 0 0 6 ] * te. ift*9 2 Ett©*Wt?tt. tlftO! 1 

EtK©m^s^->^rA(cfe^T. Bjsassisg^tt. a 
\wmn®**.m 531 1 ©HM<t#a & . msa 1 © 
Bg#{t \jX%2 (DB%mmmft®z£.&iT 5 si 2 ©aw 

{t*«±4A«U ttGBEttKB. MBStlWSOM 
EH 2 ©**<t#««: «fc 0 Bg-5f < b 3 ft fcH 2 ©Bg-sHb& 

nrts*a^Lr8tE» i ©ns*{fc!a:W3S*R»T 5 

»1 ©8Wfl;#K4ft«U MEHHtit. ttEBIE 
SS©£iTB3 1 ©aHHfc#atc J: tifcJR 1 ©Bg 

# fb&Hrtgfca-sf UrmaURAS^Kff r 5*2 © 

[0 00 7] *fc. »3|B«3E«©»WCB. M3S92 

EttorettX!'*?- Atcte^-r. ME* l ©Bg-if<b# 
SB. !»#K±9*rb*ifcSairt8*. *l©ftjl£l 
£flH>TBg#{bU KSUC^jlSI*. WEfti+SS© 
J»l©5»Hi*fflC>-CflHWkl/. MES2©Bg^{b#S 
B. liaEJfn©Bg-*Hb&llft3£. *2©*il&£ffll> 
TBg^bL/. &* 2 ©£»«£. firEBE&H©*2© 
&&3g|£ffit,>TBg^bU MESH ©«#fc*BB. Bg 
*Ht 5 2 ©*ii^>& . «TE9 2 ©<5>P§^«: »JW 
5»2©ieWSI*ffll»'Ca#L.-ClKB»2©*ail*8l 
»T 5*2 ©#»««#«£. a#$nfc*2©«jl 
«*ffli>T. B!iE»2©Bg^{bS^§?ra^t-Ci)E 

* i ©Bg#{bSMrtS=&sxff T5m2 ©Bg#<bs^rtS 

'«^b#S£ ; &{tA. ME92©fll4<b^SB. Bg#<b 

^n/c^icsaa^. «te» i ©^Ha«:»j£:r4» 
i ©iHS«*ffli»ra#o-c msM i ©saa*BW»r 
5mi©ftasia^#ig£. a^$nfcmi©ftii£i?: 
«ht, ftE»i©w#{k!aairtSSra#Lrijiffii* 

^.4C£?:#@!:£T5. 

[ 0 0 0 8 ] * tc, N$fl4E*©A93'CB. 1 
^> b 3 ©^fnA^EiRwrn^f fS^i^xf- Atctet^ 
r. BoEBa^BB. iaai#©jEatt*BHr' > «<. mi 

>P«8t£01'«^9'r>FS«#A««iL. UES 

MrtS5:Bg^bb. MEBESIg(Cj#fg-r5m3©Bg^ 
{b^S £ . MBnEMRD ?9 -f>F J: 9 £ 

ff #S £*« A 5 C £ *fif* £ I" 5. 
[ 0 0 0 9 ] *fc. IM0|5Ett©miir». 1**^ 1 

^(,»U4©i,» - fn3&5©E*8©*-?-SSl*>xf'A«:tet,> 
T. flVEJMt&BB. MEfiiratcMOrttSltim^ 

nm £ £ t tcssT 5 §fs«a t zm? zct 

£1"5. 

[0 0 10] Slfc. 8«3jG16Ett©l6W-CB < »*«3 
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r. uaB*iofina*»«tcf»i©ieffi(i. tthwtm 

IBS2©&W8*5<*:C/S2©li«»tt. BflieiSH 

[ooi i ] i&ottfm&wt&r ztttotc. s»*5 

ffieiSSEgaii. an#©BH*m>. BHShfcHte 
tt. fiieB§^{b£ttfcrt£?£fjiemitgaK:iM{IU ir 

E»tt««Kj: -»riji2Bi^i:aw3S*a#i/-csai 

(0 0 1 2 ] *fc. ft#9f8ielt©ft9]'?B. H§#:S7 

E»wtwai*ttH:*ji»r. #jie8t3?ig*«, fries 

gat*. 6WE«a8a*Jc j: o * #<ts nfcm-^ftjaairt 
SK»i/r^7^>K*«*aao. friean^w:. 20 

if*. 

[0 0 131S/C ■$a9eti®jMrc». I»#^7 

«. «SfSfi:^#tc«J:Otf^n/cfi:^rtg?:. Sl©&il 

u lines 1 ©#ait€. frie*it$ia©s 1 ©&&3H 
*»i»rit<wbi/. «B»i©flHWfcWirt«*. S2 

j#u miles 2©£ii^£. frieisSE$ia©S2©&Kj 30 
Si^ffl^rBg^bL/. Bi)ieBg^fbamrtg©a^br 

tt. fFlBBg-^{b$n- f cS2©itii^. frieS2©&ps 

«c»i&r ss 2 ©asffli*ffli» l t fries 2 © 

r, fjieS2©Bi^b!s«rtg ; &a-f L-rg5iesi©Bi 
^tawnstwiu mrieBg-^{b$nfcsi©«ii^ 

*. fJlBS 1 ©5»MKc*tJ&f 4* 1 OfBfflttSHT 

a# orfrses 1 ©ftaa*wa 0. fri2a#s n/cs 

[ 0 0 1 4 3 *fc. nWM 1 OKMOIWCtt. 

7 t£^b 9 ©^rn*^ies£©m-f«^iSK:*5i»T. 
traj»rt©c»t,T»5!mitt*4«u friean^s 
imtBmmn 1 1 t> tcsar s c £ «n« £ ? 4. 
[0 0 1 5 ] tfc. a*« 1 1 kuobe-ck. n$q 
7)tt,>i/ 1 o©i>-rn*Hciee©m-?ts»^cfc^ 
r. friesi©^niiteJ;D''Si©»sssi. tte>cwc«r 

ieS2©^HI8*JJ:CJ t S2©«fSBatt. BSE«a 
ifcttJMtSSBtcfflWTiJfiett. *SKflNfcWiat/&l» 
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[0 0 1 6 ] C©^bjt«, * ? h7-iHC&fc£;*i-i/c 

£. file* v v v-?^&w.zt\tasmkw.<<t& osss 
l. frieiga^n/cSHrt^Bi^bL-c. frse*? f 

atci^to, frie^f+^acci-o-cfrieBf^bSMrtif 

X^-;*©$§/J\ ft*&SK>£ffllE©1St&. »l+5X©PA 
[0017] 

©m^sftwr-s. 

A. JEffi£S©tttl$ 

-1. 1-2, -, l-ntt. &XR(cim$ti1tWli 

v$><o. y ^ a > tr » - * & i'^ t>ni&-& nr t,> 

£„ KSOEMHU - 1~1 -nti. -f F 7 K 

£&3*vcc»£. &ns*i - 1-1 -ntt. ncfi 

IGJrfclKSMr (n#) RBStiTfcO. *©g*a£i!t 

faa(Sfrjaa{-r*wi«©»«:)£crs»is>nTt» 

4. 

[ooi8] ±ie&ifs$* i - i - i - n «. mm® 

[0019] fiM^^ 1 - 1 - 1 - n©* -j 

ti«tt<sr*A*T4. id. mut. ® 

ID, A^7-Ktt. JW»S»©J2 

[ 0 0 2 0 3 fcfc. &SBS£ 1 - 1 - 1 - n tt> 
©a^«cB«3tir<>j:i»*J. COtg^. ^S©tS^ffl 

[0 02 1 ] SE*-^2tt. -f f-7?r^L 
TSH«*1 - 1-1 -nKSttU, JhEID. 
— K. K£B4£*«#U **i6tt«*)«*l/r»3il 
#4ISE-rS. Sfc. 82fiE-9--^2«. <02-*?Y 
7 *^0-C«a«l* 1 - 1 - 1 - n ICttLX . tttt* tit 
$8 (&g. ««. *aifit. !9X«i^l - 1 - 

i -n*>e>©smttfR (Bf^biS) 4i?*frm& 
«. fi^s*i - i - 1 -n*»6©Bt^bsnfca»« 



«*. a^r43#©J»t*— 'U- 1. 4-2, 4- 

s*#©BE**f ■»*»). aswarawiLfcOT 

afcat^BE^-^-^fcftiTt,^. S&SE7 5 - 
*-<-*3tt. 8«#«©ID. Sir. tt 

[00223 mftif-'U- 1 ~4-3«. ^ti-ena* 
e>&*. mtH--' *4- 1-4-3 «» -en-en io 

-;U-lM-3tt, SElf-'<2#>*5>©S:lf 

UNRtcttor. W$L-?-^2t>c<iiZ>T -tit* 

El/. aMS^iJ^*4)S • ttflDU SI§t-f-*^-*5 

- 1 , 5 - 2 , 5-3 Kttuws. •en-enomitif- 

yU-l~4-3K«t 5*ttfeS». 5<- 3 KM£ $ ft. 

[0023] fcfc. ±.%btc®&V->-<2*S Hum? 
-^4-1-4-3 T'ti. SUti (R©lt*ft&ft4*J: 20 

!!©£(£ te<fcO*S£liS«. IC#-F&£'© 

c©fc«e>. ffitkmmmbtc^v -jyvcztj; 
^©-c. i&g&©«&©$! (c©wr«2. msf-it-^ 

©H£K:W3«JI) /c^S^fciCWt-^b^m*. Tig 

[0 024] B . m^MBOIb^Xic . m 3 K.Tjk't va 30 
-9=-+- h^Mlur*Jiife}f^©ttmcot,i-ci¥^c 

5tt. ±IBS:m^*T©SS. SSlf-^-C©B8«. * 
tH--AT©SM©^- ; &^-r8l^:liCC*-S. 
[ 0 0 2 5 ] KH^te. *»S*©***>6-f:'*-* 
v F£fl-LT&E1>---'<«:7iHzXl<. IgE^-^*^ 

£') fcaiiTS Uf^S 1) . SSIt-^2tt. § 
»t,fc«*#«:*H,'C I D (ttlUHftSff) . PW (/< 40 

*5|5*Bf8Lftl>W*tfcBS©'C. 3Hf¥a0. BE? 

-^2 (ffnasf) w^ea»WK*«»«:*H/-ci'- 

[0 02 6] &(C. fa3KHtCtt*4. 83K#«e%©Ml 
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tcsasn/c «a«i3Ki-i ( i = i-n) frii&m 
[0027] am^--'<2« > v vizfti, 

T. ±I2&H$3U - i K*tl/T I D. KfcJ: 

tt. K»$*l - i ©*7*A*jU2p<=>. g^(C8ii<* 
ftfci/-;Utt*tt#*K:E|]:#:snfcI D. ^X9-F, 
fc<fc£>'gi£B (MMDD) iXfith Uf-v7*S 
5), ID, -f>if-*^7^Lt 

be*-. '>*2«caifi$ns. 

[0 028] BH-9--^2 tt. ±SEt2^ffi* 1 - i *>6 
A*S*ifc, ID. '^9- K, fc<fct>*§t£B*. BE 

*>. -s&gTtt&i^&i* 

M3£!5f5 1 - i Ki*{f Uf^ 7-S7). SH^tflE 

atBastiftfrofcJi^tt. -e-©M%SM«*i - i 

[0 02 9] g^S* 1 - i KUtpS 

8 ) . &M4bb* 1 - i Tit. ^4 tC^-T K. a 

!R$nfc«ffl*©it#g (wr. samtK) 

K^fg-r^ Uf^S9) . BaEU--^2-C«. 04 

h7£/)-L-C. S^«g*l - i tC^df i (^f'^S 
10). S^ffi*l - i-Ctt. I4(CS5t<t^C. ±E 
7? 4> ^^^^Tyy'y -{ > K U fr^? 

^¥« ; S:mf#-r'5 (^f77'S 11). C©ct^(C, ^ 
7^>FS«*»>5Cit?. iSiI1f-^'2T«. 

«14©RE). -tL-C. ISEIf-^'tcJrO. -e©SM* 
*5*Ar$, 5 C i . ^©SMrtS^a^^^Afc J: S t> 

Esnacitc^ta. 

[0030] w > F**«©*ac©«**-r. 12 
i-ra. *fcfetT©ai»»n©i!*©*r©aw-c* 

xil/C!8Elf--<'< A ^ft$-£. Bffi1>--^Kx©dft 
*yiLT«a«B*^a#-rS. C©y*«^5^>F» 
jaHKRtty&r-ClifcJirS. d = l/et 
S>i©-C, B»^*«m©d*4&0. cniimtc^-T 

ag^-s-©*)©^*)*. 

[0031] sam^ i - i rtt. b 5 tc^-r «t 

KiOSHl/fca (Xt» 12). 3 6K, imB 
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tc£*)&iiu Uf'^S 13), -f>*-*5> h7£ 
5 CCTjrTJ: MC, WM©i*ISB©#«:H§*l/ 

s 1 4 ) . atw-'u - 1-4-3 tcmatz. msf 

•^•-^'4- l~4-3-C«. 0 5(C7nf «t5fc, ttfSSA 
Uf-?7*S 15), TcO&HltfR tfi'S* 

[0 03 2 ] tlTCC. ±iaSM^S 1-1-1-nTO 
g?£f. I2fflJ-->s*2-C©B8tt. ftH-9--^4-l~4- 

37©MW£^t>TJ:9ftlffl(ci&iB1"*. ccr. 06 io 

tt. ±IB&SI$*T-©ffit4©»iHB&®^£^T«3:0-C 
*S. £?c 07 te, ±ffi!2Ht>--^ , fc«tO , *lt^-^' 

-c©ggs©i^*ffl^^^-r«^:Bi"c*5. 

[0 0 3 3 ] 1 - 1 - 1 - n Ttt. 06 (CjjVT 

akAlt?B#{fcT5CiK«t») (Xf^Sal) , 

«HAK«to*sutea. Jifa^aHKAi^, 

w?4-i ( i = 1. 2. 3) *JfiHl/n»5fiH«K 

b ncfcoflHWtra Uf^sa2) . ^cc, i?# 

ttbfcfSOHItt (»«A) 5r. <*6CC. *ji«KA2-C 20 
^kT5C£(C«t»3 (X7-9?Sa3) . t-tiSSBtec): 
»)««Lfca. ±IB*jISiKA2£. SHU— ^2#fi 

a 4) . CflfcJ:»). &g{M8tt. MSA (rtfflj) i« 
®iB (WW) -e-niC®% (Bf^Ht) StltcCtlCtj: 
5. ttZ*K«4Mk $ tlfc&gflmtt. 
7^/M/TigaE1t-^'2^^g?nS. 
[0 03 4] !SaE-?-^2Tfct. 17 ( a ) iCTjVJ-J: 5 
K. ±E4i«HiKB2K»l6rS8afllKC2«:j:0. 
flHWb3hfc*iMlKA2*a<»l/T±E*jMIKA2 30 

(Xf'^Sbl) . ^j!ilKA2-C. ±13 
-fitcBg^t$n/cS^t*fS (WW : SflSA. *HM : « 
«B) Z'&^?Z>ttV. *HM©M®B£g§ftt"* U 
f^Sb2). -etr. liiliArffi£f;*ftfc&ilti!*S 

4 - 1 -4 - 3K.mmz>. 

[0 03 5 ] HOW-**- i (i = l. 2. 3>r 
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(54) {Title of invention} Electronic voting system and electronic voting method 



(57) {Abstract} 

{Problem} To achieve reduction in amount of labor, reduction 
of ballot opening space, elimination of invalid ballots and 
questionable ballots, and prevention of counting errors. 
{Solution} Voters vote at voting tenninals 1-1 through 1-n by 
using a touch panel. An authentication server 2 generates a blind 
signature for the vote information to authenticate the voter. 
Voting terminals 1-1 through 1-n seal the vote information in a 
double electronic envelope by means of encryption techniques 
and send it over the internet 7 to the authentication server 2. The 
authentication server 2 unseals the outer envelope and sends the 
result to three counting servers 4-1 through 4-3. Each of the 
counting servers 4-1 through 4-3 unseals the inner envelope 
and performs counting based on the vote content. After opening 
of ballots is completed, the counting servers 4-1 through 4-3 
compare the collected and counted results of voting, and in case 
a discrepancy is discovered, determine the correct value by 
majority decision. 
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1-1, 1-2, 1-n: Voting terminal 
2: Authentication server 
3: Authentication DB 

4- 1 , 4-2, 4-3: Counting server 

5- 1,5-2, 5-3: Counting DB 
7: Internet 

A: ID (voter identifier) 
PW (password) 
Name 
Address 

Voting status (registered, voting in progress, voting completed) 
Vote information 
Vote identifier 



B: 
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{Scope of patent Claims} 

{Claim 1} An electronic voting system distinguished in that it 
comprises: 

a voting terminal connected to a network, which encrypts the 
content of votes cast by voters for candidates and generates 
encrypted vote content; 

an authentication device which authenticates said voters at said 
voting terminal via said network; and 

a counting device which decrypts the encrypted vote content 

obtained from said voting terminal via said authentication 

device to acquire the vote content, and counts the votes obtained 

by candidates based on said vote content. 

{Claim 2} An electronic voting system as described in Claim 1, 

distinguished in that: 

said voting terminal comprises 

a first encryption means which encrypts the content of the vote 
cast by the voter to generate a first encrypted vote content; and 
a second encryption means which encrypts the first encrypted 
vote content encrypted by said first encryption means to 
generated a second encrypted vote content; 
said authentication device comprises: 

a first decryption means which decrypts the second encrypted 
vote content encrypted by said second encryption means of said 
voting terminal to obtain said first encrypted vote content; 
and said counting device comprises: 

a second decryption means which decrypts the first encrypted 

vote content decrypted by said first decryption means of said 

authentication device to obtain said vote content. 

{Claim 3} An electronic voting system as described in Claim 2, 

distinguished in that said first encryption means 

encrypts the content of the vote cast by the voter using a first 

common key and encrypts said first common key using a first 

public key of said counting device; 

said second encryption means 

encrypts said first encrypted vote content using a second 
common key and encrypts said second common key using a 
second public key of said authentication device; 
said first decryption means comprises a second common key 
decryption means which decrypts the encrypted second common 
key using a second secret key corresponding to said second 
public key to obtain said second common key, and a second 
encrypted vote content decryption means which decrypts said 
second encrypted vote content using the decrypted second 
common key to obtain said first encrypted vote content; 
and said second decryption means comprises a first common 
key decryption means which decrypts the encrypted first 
common key using a first secret key corresponding to said first 
public key to obtain said first common key, and a first encrypted 
vote content decryption means which decrypts said first 
encrypted vote content using the decrypted first common key to 
obtain said vote content. 

{Claim 4} An electronic voting system as described in any of 
Claims 1 through 3, distinguished in that 
said authentication device comprises: 

a blind signing means which generates a blind signature for the 
vote content encrypted by said voting terminal to authenticate 
the legitimacy of the voter; 
and said voting terminal comprises: 
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a third encryption means which encrypts the content of the vote 
for candidates selected by the voter and transmits it to said 
authentication device; and 

a signature acquisition means which acquires signature 

information from the blind signature generated by the blind 

signing means of said authentication device. 

{Claim 5} An electronic voting system as described in any of 

Claims 1 through 4, distinguished in that: 

said counting device comprises: 

an identification information generating means which generates 
identification information for said vote content; and 
a storage means which stores said vote content together with 
said identification information. 

{Claim 6} An electronic voting system as described in any of 
Claims 3 through 5, distinguished in that said first public key 
and first secret key as well as said second public key and second 
secret key are each generated and managed within an IC card 
that can be installed in and removed from said authentication 
device or said counting device and which is protected so as to 
prevent external leakage of information. 
{Claim 7} An electronic voting method distinguished in that: 
a voter casts a vote from a voting terminal connected to a 
network; 

said cast vote content is encrypted and transmitted to an 
authentication device connected to said network; 
said authentication device performs authentication of the voter, 
and if he was authenticated, transmits said encrypted content to 
said counting device; 

said encrypted vote content is decrypted by said counting device 
to obtain the vote content; and 

the votes obtained by candidates are counted based on said vote 
content. 

{Claim 8} An electronic voting method as described in Claim 7, 
distinguished in that: 

said voting terminal encrypts said vote content to generate 
encrypted vote content; 

said authentication device generates a blind signature for the 
encrypted vote content encrypted by said voting terminal; and 
said voting terminal obtains signature information from said 
blind signature. 

{Claim 9} An electronic voting method as described in Claim 7, 

distinguished in that: 

in the encryption of said vote content, 

the content of the vote cast by said voter is encrypted using a 
first common key to generate said first encrypted vote content; 
said first common key is encrypted using a first public key of 
said counting device; 

said first encrypted vote content is encrypted using a second 

common key to generated second encrypted vote content; 

said second common key is encrypted using a second public key 

of said authentication device; 

and in the decryption of said encrypted vote content, 

said encrypted second common key is decrypted using a second 

secret key corresponding to said second public key to obtain 

said second common key; 

said second encrypted vote content is decrypted using said 
decrypted second common key to obtain said first encrypted 
vote content; 
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said encrypted first common key is decrypted using a first secret 
key corresponding to said first public key to obtain said first 
common key; and 

said first encrypted vote content is decrypted using said 
decrypted first common key to obtain the vote content. 
{Claim 10} An electronic voting method as described in any of 
Claims 7 through 9, distinguished in that identification 
information is generated for said vote content, and said vote 
content is stored together with said identification information. 
{Claim 1 1 } An electronic voting method as described in any of 
Claims 7 through 10, distinguished in that said first public key 
and first secret key as well as said second public key and second 
secret key are each generated and managed within an IC card 
that can be installed in and removed from the authentication 
device or counting device and which is protected so as to 
prevent external leakage of information. 
{Detailed description of the invention} 
{0001} 

{Technical field of the invention} The present invention relates 
to electronic voting systems and electronic voting method 
suitably used in voting in national political elections, regional 
elections and the like. 
{0002} 

{Prior art} In the prior art, voting in national political elections, 
regional elections and the like has been carried out by having 
eligible voters write the names of candidates on ballots at 
polling places, gathering said ballots, and confirming and 
counting the candidate names written on the ballots, one by one, 
with much labor. 
{0003} 

{Problem to be solved by the invention} However, in the 
aforementioned prior art, large amounts of labor and ballot 
opening space is required. Furthermore, since the voter name is 
written by hand by the voter, invalid votes and questionable 
votes due to clerical errors cannot be eliminated. Furthermore, 
due to the visual confirmation by people, there was the problem 
that counting errors would also occur. 

{0004} This invention was made in view of the above situation, 
and has the objective of providing an electronic voting system 
and electronic voting method capable of achieving reduction in 
amount of labor, reduction of ballot opening space, elimination 
of invalid ballots and questionable ballots, and prevention of 
counting errors. 
{0005} 

{Means of solving the problem} To resolve the aforesaid 
problems, the invention described in Claim 1 is distinguished in 
that it comprises a voting tenxiinal connected to a network, 
which encrypts the content of votes cast by voters for candidates 
and generates encrypted vote content; an authentication device 
which authenticates said voters at said voting terminal via said 
network; and a counting device which decrypts the encrypted 
vote content obtained from said voting terminal via said 
authentication device to acquire the vote content, and counts the 
votes obtained by candidates based on said vote content. 
{0006} Furthermore, the invention described in Claim 2 is 
distinguished in that, in the electronic voting system described 
in Claim 1, said voting terminal comprises: a first encryption 
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means which encrypts the content of the vote cast by the voter 
to generate a first encrypted vote content, and a second 
encryption means which encrypts the first encrypted vote 
content encrypted by said first encryption means to generated a 
second encrypted vote content; said authentication device 
comprises a first decryption means which decrypts the second 
encrypted vote content encrypted by said second encryption 
means of said voting terminal to obtain said first encrypted vote 
content; and said counting device comprises a second 
decryption means which decrypts the first encrypted vote 
content decrypted by said first decryption means of said 
authentication device to obtain said vote content. 
{0007} Furthermore, the invention described in Claim 3 is 
distinguished in that, in the electronic voting method system 
described in Claim 2, said first encryption means encrypts the 
content of the vote cast by the voter using a first common key 
and encrypts said first common key using a first public key of 
said counting device; said second encryption means encrypts 
said first encrypted vote content using a second common key 
and encrypts said second common key using a second public 
key of said authentication device; said first decryption means 
comprises: a second common key decryption means which 
decrypts the encrypted second common key using a second 
secret key corresponding to said second public key to obtain 
said second common key, and a second encrypted vote content 
decryption means which decrypts said second encrypted vote 
content using the decrypted second common key to obtain said 
first encrypted vote content; and said second decryption means 
comprises: a first common key decryption means which 
decrypts the encrypted first common key using a first secret key 
corresponding to said first public key to obtain said first 
common key, and a first encrypted vote content decryption 
means which decrypts said first encrypted vote content using the 
decrypted first common key to obtain said vote content. 
{0008} Furthermore, the invention described in Claim 4 is 
distinguished in that, in the electronic voting system as 
described in any of Claims 1 through 3, said authentication 
device comprises a blind signing means which generates a blind 
signature for the vote content encrypted by said voting terminal 
to authenticate the legitimacy of the voter; and said voting 
terminal comprises a third encryption means which encrypts the 
content of the vote for candidates selected by the voter and 
transmits it to said authentication device, and a signature 
acquisition means which acquires signature information from 
the blind signature generated by the blind signing means of said 
authentication device. 

{0009} Furthermore, the invention described in Claim 5 is 
distinguished in that, in the electronic voting system as 
described in any of Claims 1 through 4, said counting device 
comprises an identification information generating means which 
generates identification information for said vote content, and a 
storage means which stores said vote content together with said 
identification information. 

{0010} Furthermore, the invention described in Claim 6 is 
distinguished in that, in the electronic voting system as 
described ; n 
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any of Claims 3 through 5, said first public key and first secret 
key as well as said second public key and second secret key are 
each generated and managed within an IC card that can be 
installed in and removed from said authentication device or said 
counting device and which is protected so as to prevent external 
leakage of information. 

{0011} To resolve the aforementioned problems, the invention 
described in Claim 7 is distinguished in that a voter casts a vote 
from a voting terminal connected to a network; said cast vote 
content is encrypted and transmitted to an authentication device 
connected to said network; said authentication device performs 
authentication of the voter, and if he was authenticated, 
transmits said encrypted content to said counting device; said 
encrypted vote content is decrypted by said counting device to 
obtain the vote content; and the votes obtained by candidates are 
counted based on said vote content. 

{0012} Furthermore, the invention described in Claim 8 is 
distinguished in that, in the electronic voting method as 
described in Claim 7, said voting terminal encrypts said vote 
content to generate encrypted vote content; said authentication 
device generates a blind signature for the encrypted vote content 
encrypted by said voting terminal; and said voting terminal 
obtains signature information from said blind signature. 
{0013} Furthermore, the invention described in Claim 9 is 
distinguished in that, in the electronic voting method as 
described in Claim 7, in the encryption of said vote content, the 
content of the vote cast by said voter is encrypted using a first 
common key to generate said first encrypted vote content; said 
first common key is encrypted using a first public key of said 
counting device; said first encrypted vote content is encrypted 
using a second common key to generated second encrypted vote 
content; said second common key is encrypted using a second 
public key of said authentication device; and in the decryption 
of said encrypted vote content, said encrypted second common 
key is decrypted using a second secret key corresponding to said 
second public key to obtain said second common key; said 
second encrypted vote content is decrypted using said decrypted 
second common key to obtain said first encrypted vote content; 
said encrypted first common key is decrypted using a first secret 
key corresponding to said first public key to obtain said first 
common key; and said first encrypted vote content is decrypted 
using said decrypted first common key to obtain the vote 
content. 

{0014} Furthermore, the invention described in Claim 10 is 
distinguished in that, in the electronic voting method as 
described in any of Claims 7 through 9, identification 
information is generated for said vote content, and said vote 
content is stored together with said identification information. 
{0015} Furthermore, the invention described in Claim 11 is 
distinguished in that, in the electronic voting method as 
described in any of Claims 7 through 10, said first public key 
and first secret key as well as said second public key and second 
secret key are each generated and managed within an IC card 
that can be installed in and removed from the authentication 
device or counting device and which is protected so as to 
prevent external leakage of information. 
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{0016} In this invention, a voter casts a vote from a voting 
terminal connected to a network; said cast vote content is 
authenticated by an authentication device connected to said 
network; said authenticated vote content is encrypted and 
transmitted to a counting device connected to said 
authentication device; said encrypted vote content is decrypted 
by said counting device to obtain the vote content; and the votes 
obtained by candidates are counted based on said vote content. 
Thus, it becomes possible to achieve reduction in amount of 
labor, reduction of ballot opening space, elimination of invalid 
ballots and questionable ballots, and prevention of counting 
errors. 
{0017} 

{Modes of embodiment of the invention} Below, modes of 
embodiment of the present invention are described using the 
drawings. 

A. Constitution of the mode of embodiment 1 
Figure 1 is a block diagram showing the constitution of an 
electronic voting system according to a mode of embodiment of 
the present invention. In Figure 1, voting terminals 1-1, 1-2, 
1-n are terminals installed at a polling place, and are made up of 
personal computers and the like. Said voting terminals 1-1 
through 1-n are connected to the internet 7. Multiple (n) voting 
tenriinals 1-1 through 1-n are installed at a single polling place, 
the number of terminals installed being determined in 
accordance with the number of eligible voters voting at the 
polling place. 

{0018} Said voting terminals 1-1 through 1-n have the function 
of encrypting candidate information, the function of decrypting 
(unblinding) digital signatures generated by the authentication 
server 2 described below, as well as the function of performing 
double encryption on candidate information and digital 
signatures, and the like. These functions (operations) will be 
discussed below. 

{0019} A voter enters an ID (voter identifier) and password for 
authenticating the voter, as well as candidates and the like, by 
touching numerical buttons on the touch panel of the voting 
terminals 1-1 through 1-n. The ID and password are for 
instance divided into groups of three columns, and each group is 
numbered. In consideration of elderly voters and the like, the ID 
and password are preferably made up of numerals only, so as to 
reduce misreading or input errors. 

{0020} The voting terminals 1-1 through 1-n may also be 
installed at a voter's home, in which case specific voting 
software needs to be installed in advance. 
{0021} The authentication server 2 requests said ID, password, 
birth date, etc. from the voting terminals 1-1 through 1-n via 
the internet 7, and verifies those pieces of information to 
authenticate the voter. Furthermore, the authentication server 2 
transmits candidate information (name, party, face photograph) 
to the voting terminals 1-1 through 1-n via the internet 7, and 
issues a digital signature (blind signature) for (encrypted) vote 
information from the voting terminals 1-1 through 1-n. 
Moreover, the authentication server 2 transmits encrypted vote 
information from the voting terminals 1-1 through 1-n to three 
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counting servers 4-1, 4-2 and 4-3, which are described below. 
Moreover, the authentication server 2 comprises an 
authentication database for performing voter authentication, 
managing voting status, etc. Said authentication database 3 
stores each voter's ID, password, name, address and voting 
status (registered, voting in progress, voting completed). 
{0022} The counting servers 4-1 through 4-3 consist of three 
physically separated servers having the same functions. The 
counting servers 4-1 through 4-3 each independently perform 
vote collection and counting. More specifically, the counting 
servers 4-1 through 4-3 verify the digital signature made by the 
authentication server 2 for vote information from the 
authentication server 2, generate and append a vote identifier 
thereto, and store it in counting databases 5-1, 5-2 and 5-3. The 
results of counting by the respective counting servers 4-1 
through 4-3 are compared to each other, and if a discrepancy is 
discovered, the correct value is determined by majority decision. 
{0023} The aforementioned authentication server 2 and 
counting servers 4-1 through 4-3 are made to perform 
encryption, decryption and digital signing of vote information; 
the generation of secret keys used in said encryption, decryption 
and digital signing, as well as decryption and signature 
generation, are performed on a storage medium such as an IC 
card. The secret key is protected so that it cannot be read out 
from the IC card. Thus, since backups against loss or the like 
cannot be made, as many signings and encryptions are 
performed as the number of secret keys (2 in this example; 3 in 
case of counting servers) to provide redundancy. 
{0024} B. Operation of the mode of embodiment 
Next, operation of the present mode of embodiment is described 
in detail with reference to the flow chart shown in Figure 3. 
Here, Figure 4 is a flow chart showing the process of obtaining a 
digital signature from the authentication server. Furthermore, 
Figure 5 is a conceptual drawing which shows the situation of 
envelope sealing at said voting terminals, unsealing at the 
authentication server and unsealing at the counting servers. 
{0025} A voter accesses the authentication server in advance 
via the internet from a terminal at his home and registers 
personal information (name, address, etc.) from an election 
administration Web screen presented by the authentication 
server (Step SI). The authentication server 2 mails a sealed 
postcard (voting card) with the ID (voter identifier) and PW 
(password) for the registered voter inscribed thereon to the 
voter's home (Step S2). Since there are eligible voters who may 
not have a terminal at home, sealed postcards (voting cards) 
may also be automatically mailed to the homes of eligible voters 
from the authentication server 2 (competent government office), 
as per the current practice. 

{0026} Next, on polling day, voters cast votes from the 
terminals at their home. Voters who do not have a terminal at 
home take the voting card mailed to their home and go to a 
polling place, and cast votes from terminals at the polling place. 
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Voters commence voting from a voting terminal 1-i (i = 1 ~ n) 
installed at home or at a polling place (Step S3). 
{0027} The authentication server 2 requests input of ID, 
password and birth date from said voting terminal 1-i via the 
internet 7 (Step S4). The voter inputs the ID, password and birth 
date (MMDD) printed on the sealed postcard mailed to his home 
via the touch panel of the voting terminal 1-i (Step S5). The ID 
and password are transmitted via the internet 7 to the 
authentication server 2. 

{0028} The authentication server 2 compares the ID, password 
and birth date input from said voting terminal 1-i against 
information in the authentication database 3 to check if this is a 
proper voter, i.e. an eligible voter, and that this is not a case of 
duplicate voting (Step S6). If the voter was authenticated as 
being legitimate, the authentication server 2 transmits candidate 
information (name, party, face photograph, etc.) via the internet 
7 to said voting terminal 1-i (Step S7). If the voter was not 
authenticated as legitimate, that fact is displayed on the voting 
terminal 1-i and processing for the voter in question is 
discontinued. 

{0029} The voter confirms the candidate information displayed 
on the voting terminal 1-i and selects (votes for) candidates 
(Step S8). The voting terminal 1-i, as shown in Figure 4, blinds 
(encrypts) the selected candidate information (hereinafter, vote 
information) and transmits it via the internet 7 to the 
authentication server 2 (Step S9). The authentication server 2, as 
shown in Figure 4, generates a digital signature (blind signature) 
for said encrypted vote information and transmits it via the 
internet 7 to the voting terminal 1-i (Step S10). The voting 
terminal 1-i, as shown in Figure 4, unblinds (decrypts) said 
blind signature to obtain a digital signature (Step SI 1). In this 
way, by using a blind signature, the authentication server 2 can 
ascertain the voter but cannot find out the vote content 
(guarantee of anonymity). Furthermore, the authentication 
server authenticates the voter's identity, that the vote content 
was produced by that voter, and that the vote was not cast in 
duplicate. 

{0030} Next, an example of the blind signing scheme is 
described. It is assumed that d is the authentication server's 
secret key, e and n are the public keys, and m is the vote 
information. Furthermore, the computational operations below 
are based on the residue of n. The voting terminal generates a 
random number r, and sends the product of r to the power of e 
and m to the authentication server as x. The authentication 
server takes x to the power of d and sends it to the voting 
terminal as y. This y is the blind signature. The voting terminal 
divides y by r. Since d = 1/e, the results of the division will be m 
to the power of d, which is the signature for m proper. 
{0031} Next, the voting terminal 1-i, as shown in Figure 5, 
seals said vote information (including digital signature) in an 
envelope A (Step SI 2), and then again seals it in an envelope 
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B (Step SI 3) and transmits it via the internet 7 to the 
authentication server 2. The authentication server 2, as shown in 
Figure 5, unseals only the outer envelope B (Step SI 4) and 
transmits the result to the counting servers 4-1 through 4-3. The 
counting servers 4-1 through 4-3, as shown in Figure 5, unseal 
the envelope A (Step SI 5) and obtain the original vote 
information (including digital signature). 
{0032} Below, the sealing of the envelope at said voting 
terminals 1-1 through 1-n, the unsealing at authentication 
server 2 and unsealing at the counting servers 4-1 through 4-3 
is described in more detail. Here, Figure 6 is a conceptual 
drawing which shows the detailed situation of sealing at said 
voting terminals. Furthermore, Figure 7 is a conceptual drawing 
which shows the detailed situation of unsealing at said 
authentication server and counting servers. 
{0033} At the voting terminals 1-1 through 1-n, as shown in 
Figure 6, the aforementioned vote information (including digital 
signature) is encrypted with a common key KA1 (Step Sal), 
thereby sealing it in envelope A, and then said common key 
KA1 is . encrypted with a public key KB1 published by the 
counting servers 4-i (i = 1, 2, 3) (Step Sa2). Next, the encrypted 
vote information (envelope A) is further encrypted with 
common key KA2 (Step Sa3) to seal it in envelope B, after 
which said common key KA2 is encrypted with a public key 
KB2 published by the authentication server 2 (Step Sa4). The 
vote information is thereby sealed (encrypted) doubly, in 
envelope A (inner) and envelope B (outer). Said double 
encrypted vote information is transmitted via the internet 7 to 
the authentication server 2. 

{0034} At the authentication server 2, as shown in Figure 7(a), 
the encrypted common key KA2 is decrypted with the secret 
key KC2 corresponding to said public key KB 2 to obtain said 
common key KA2 (Step Sbl) and said double encrypted vote 
information (inner: envelope A; outer: envelope B) is decrypted 
with said common key KA2 to unseal the outer envelope B 
(Step Sb2). The vote information sealed in envelope A is then 
transmitted to the counting servers 4-1 through 4-3. 
{0035} At the counting server 4-i (i = 1, 2, 3), as shown in 
Figure 7(b), the encrypted common key KA1 is decrypted by the 
secret key KC1 corresponding to said public key KB1 to obtain 
the common key KA1 (Step Scl), and said vote information 
(envelope A) is decrypted with said common key KA1 to unseal 
envelope A (Step Sc2). At this point, the counting server 4-i 
obtains the original vote information (including digital 
signature). 

{0036} In the foregoing description, the present mode of 
embodiment employs three counting servers 4-1 through 4-3, 
so in actuality, the counting servers would each generate their 
respective secret key KC1-1, KC1-2 or KC1-3 and the public 
key KB 1-1, KB 1-2 or KB 1-3 corresponding to said secret key. 
Then the voting terminal 1-i, when sealing the vote information 
in envelope A, would encrypt the common key KA1 with each 
of said public keys KB 1-1, KB 1-2 and KB1-3. 
{0037} Returning to Figure 3, next, the counting servers 4-1 
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through 4-3 verify the authentication server signature based on 
the digital signature to check whether or not the vote 
information has been authenticated by the authentication server 
2 (Step SI 6). Next, the counting servers 4-1 through 4-3 
generate an identifier, for instance by taking the current date, 
hour, minute, second, millisecond and microsecond data as a 
hash value (Step SI 7), append it to the vote information and 
store it in the counting databases 5-1 through 5-3, and also 
count the vote based on the vote information. After completion 
of ballot opening, the voting results from the ballots collected 
and counted independently at each of the counting servers 4-1 
through 4-3 are compared, and if a discrepancy is discovered, 
the correct value is determined by majority decision. 
{0038} 

{Effect of the invention} As described above, according to the 
present invention, voters cast votes from voting terminals 
connected to a network, said cast vote content is authenticated 
by an authentication device connected to said network, said 
authenticated vote content is encrypted and transmitted via said 
network to a counting device connected to said authentication 
device, said encrypted vote content is decrypted by said 
counting device to obtain the vote content, and the votes 
obtained by candidates are counted based on said vote content, 
thereby providing the advantages of allowing one to achieve 
reduction in amount of labor, reduction of ballot opening space, 
elimination of invalid ballots and questionable ballots, and 
prevention of counting errors. 
{Brief description of the drawings} 

{Figure 1 } A block diagram showing the constitution of an 
electronic voting system according to a mode of embodiment of 
the present invention. 

{Figure 2} A conceptual diagram showing the constitution of 
the voter ID and password according to the present mode of 
embodiment. 

{Figure 3} A flow chart explaining the operation of an 
electronic voting system according to a mode of embodiment of 
the present invention. 

{Figure 4} A flow chart showing the process of obtaining a 

digital signature from the authentication server. 

{Figure 5} A conceptual drawing showing the situation of 

envelope sealing at voting terminals, unsealing at the 

authentication server, and unsealing at the counting servers. 

{Figure 6} A conceptual drawing which shows the detailed 

situation of envelope sealing at the voting terminals. 

{Figure 7} A conceptual drawing which shows the detailed 

situation of envelope unsealing at the authentication server and 

counting servers. 

{Description of captions} 

1-1 - 1-n Voting terminal 

2 Authentication server (authentication device) 

3 Authenticate database 

4- 1 - 4-3 Counting server (counting device) 

5- 1 ~ 5-3 Counting database 
7 Internet 
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